These hunt-native artifacts are the source of truth for the case.
Creates:
.planning/config.json
.planning/MISSION.md
.planning/HYPOTHESES.md
.planning/SUCCESS_CRITERIA.md
.planning/HUNTMAP.md
.planning/STATE.md
.planning/QUERIES/
.planning/RECEIPTS/
Bootstrap should only scaffold the case. Do not seed sample queries, sample receipts, or completed phases.
Unknown scope details, data sources, operators, and constraints must remain TBD unless the operator confirms them.
Confirmed bootstrap facts such as the case name, mode, opened date, and initial phase/status must be filled immediately.
After this command: Run /hunt-shape-hypothesis or /hunt-plan 1.
1---2name: hunt-new-case3description: Initialize a threat hunting case from a signal, detection, intel lead, or analyst suspicion4---5
6<context>
7**Flags:**
8- `--auto` - Use the supplied signal brief as the starting point and ask only for missing critical facts.
9- `--pack <id>` - Bootstrap the case from a built-in or local hunt pack. Use `thrunt-tools pack bootstrap <id>` to inspect the generated mission, hypothesis, and phase seed content.
10</context>
11
12<objective>
13Initialize a threat hunting case.
14
15These hunt-native artifacts are the source of truth for the case.
16
17**Creates:**
18- `.planning/config.json`
19- `.planning/MISSION.md`
20- `.planning/HYPOTHESES.md`
21- `.planning/SUCCESS_CRITERIA.md`
22- `.planning/HUNTMAP.md`
23- `.planning/STATE.md`
24- `.planning/QUERIES/`
25- `.planning/RECEIPTS/`
26
27Bootstrap should only scaffold the case. Do not seed sample queries, sample receipts, or completed phases.
28Unknown scope details, data sources, operators, and constraints must remain `TBD` unless the operator confirms them.
29Confirmed bootstrap facts such as the case name, mode, opened date, and initial phase/status must be filled immediately.
30
31**After this command:** Run `/hunt-shape-hypothesis` or `/hunt-plan 1`.
32</objective>
33
34<execution_context>
35@.github/thrunt-god/workflows/hunt-bootstrap.md
36@.github/thrunt-god/templates/config.json
37@.github/thrunt-god/templates/mission.md
38@.github/thrunt-god/templates/hypotheses.md
39@.github/thrunt-god/templates/success-criteria.md
40@.github/thrunt-god/templates/huntmap.md
41@.github/thrunt-god/templates/hunt-state.md
42</execution_context>
43
44<process>
45Execute the bootstrap workflow from @.github/thrunt-god/workflows/hunt-bootstrap.md in case mode.
46Focus on turning the input signal into a scoped case with explicit hypotheses, data sources, and evidence requirements.
47When `--pack <id>` is present, use the pack bootstrap output as the default case skeleton and ask only for the missing pack parameters or signal-specific overrides.
48Create `.planning/QUERIES/` and `.planning/RECEIPTS/` as empty directories only.
49Do not load query-log or receipt templates during bootstrap; those belong to `/hunt-run` after real execution begins.
50Default behavior is scaffold-first: write confirmed facts only and leave unknown values as `TBD` instead of inventing sample content.
51Create `.planning/config.json` during bootstrap if it does not already exist so runtime, settings, and connector commands are immediately usable.
52Never hand-write `.planning/config.json`; use `thrunt-tools config-new-program` and `thrunt-tools config-set` so the file stays valid THRUNT config.
53Use built-in connector ids exactly as the runtime registers them, for example `splunk` and `elastic`; do not substitute `elasticsearch`.
54When writing connector profiles, use `base_url` for the runtime URL field; do not invent or substitute `endpoint`.
55Only configure connector profiles when auth type and secret ref names are confirmed. Never invent placeholder env vars or placeholder secrets for blocked connectors.
56When writing `secret_refs`, each confirmed secret must use the THRUNT object shape `{ "type": "env", "value": "ENV_VAR_NAME" }` rather than a raw string.
57Keep connector narrative, status notes, and access commentary in `ENVIRONMENT.md`, not in ad hoc config keys.
58Do not leave bootstrap-known fields as `TBD` after writing the files.
59Write the hunt artifacts directly.
60</process>